About this course
The General Data Protection Regulation (GDPR) is the European Union's data protection law, and its reach extends well beyond companies headquartered in Europe: any organization that processes the personal data of individuals in the EU can fall under its scope. This course walks corporate staff and all employees through GDPR's core requirements in practical terms, focused on what day-to-day work actually needs to look like to stay compliant.
GDPR is built around seven core principles set out in Article 5: lawfulness, fairness and transparency; purpose limitation; data minimization; accuracy; storage limitation; integrity and confidentiality; and accountability. In practice, this means personal data can only be collected for a specific, disclosed purpose, only the data actually needed should be collected, and organizations must be able to demonstrate their compliance, not just claim it.
Before processing personal data, an organization must establish a valid lawful basis, such as consent, contractual necessity, legal obligation, or legitimate interest. GDPR also grants individuals a defined set of data subject rights, including the right to access their data, rectify inaccuracies, request erasure ("the right to be forgotten"), restrict processing, receive their data in a portable format, and object to certain types of processing. Employees who handle customer or employee data need to recognize these requests when they arrive and know how to route them correctly.
One of GDPR's most operationally significant requirements is breach notification: under Article 33, organizations must notify the relevant supervisory authority within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to pose a risk to individuals' rights and freedoms. That 72-hour clock starts as soon as the organization has reasonable awareness of a likely breach, which is why fast internal reporting is essential, not optional.
This course is designed for all employees and corporate staff, particularly those who handle customer, employee, or vendor personal data. After completing it, learners will be able to identify what counts as personal data under GDPR, explain the lawful bases for processing it, recognize and route data subject rights requests, and understand why immediate internal reporting of a suspected data breach is critical to meeting the 72-hour notification requirement.
Want this tailored to your organization's policies? Build your own with AI or book a demo.